Server | Apache/2.4.10 |
Expires | Thu, 19 Nov 1981 08:52:00 GMT |
Pragma | no-cache |
Cache-Control | no-cache, no-store, must-revalidate, private |
Strict-Transport-Security | max-age=31536000; |
X-Content-Type-Options | nosniff |
X-XSS-Protection | 1; mode=block |
Access-Control-Allow-Origin | * |
Access-Control-Allow-Methods | POST, GET, OPTIONS |
Access-Control-Allow-Headers | X-Requested-With, X-App-Token, X-App-Session, X-Touch, MBM-Handle-Errors-Generically, Mbm-Authorized-App, Content-Type |
Vary | Accept-Encoding |
Content-Encoding | gzip |
Content-Security-Policy | default-src 'self' https://piwik.jstmail.de *.facebook.net *.facebook.com *.youtube.com; script-src 'self' 'unsafe-eval' https://piwik.jstmail.de *.facebook.net *.facebook.com *.youtube.com *.ytimg.com www.google-analytics.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://piwik.jstmail.de mitbringen.net play.google.com linkmaker.itunes.apple.com www.google-analytics.com *.ssl-images-amazon.com *.images-amazon.com *.facebook.net *.facebook.com https://www.paypalobjects.com; connect-src 'self' https://piwik.jstmail.de www.google-analytics.com wss://dev.mitbringen.net wss://mitbringen.net |
Keep-Alive | timeout=5, max=100 |
Connection | Keep-Alive |
Content-Type | text/html; charset=UTF-8 |